cms-examples.pl revision 1.1.1.1 1 1.1 christos # test/cms-examples.pl
2 1.1 christos # Written by Dr Stephen N Henson (steve (at] openssl.org) for the OpenSSL
3 1.1 christos # project.
4 1.1 christos #
5 1.1 christos # ====================================================================
6 1.1 christos # Copyright (c) 2008 The OpenSSL Project. All rights reserved.
7 1.1 christos #
8 1.1 christos # Redistribution and use in source and binary forms, with or without
9 1.1 christos # modification, are permitted provided that the following conditions
10 1.1 christos # are met:
11 1.1 christos #
12 1.1 christos # 1. Redistributions of source code must retain the above copyright
13 1.1 christos # notice, this list of conditions and the following disclaimer.
14 1.1 christos #
15 1.1 christos # 2. Redistributions in binary form must reproduce the above copyright
16 1.1 christos # notice, this list of conditions and the following disclaimer in
17 1.1 christos # the documentation and/or other materials provided with the
18 1.1 christos # distribution.
19 1.1 christos #
20 1.1 christos # 3. All advertising materials mentioning features or use of this
21 1.1 christos # software must display the following acknowledgment:
22 1.1 christos # "This product includes software developed by the OpenSSL Project
23 1.1 christos # for use in the OpenSSL Toolkit. (http://www.OpenSSL.org/)"
24 1.1 christos #
25 1.1 christos # 4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to
26 1.1 christos # endorse or promote products derived from this software without
27 1.1 christos # prior written permission. For written permission, please contact
28 1.1 christos # licensing (at] OpenSSL.org.
29 1.1 christos #
30 1.1 christos # 5. Products derived from this software may not be called "OpenSSL"
31 1.1 christos # nor may "OpenSSL" appear in their names without prior written
32 1.1 christos # permission of the OpenSSL Project.
33 1.1 christos #
34 1.1 christos # 6. Redistributions of any form whatsoever must retain the following
35 1.1 christos # acknowledgment:
36 1.1 christos # "This product includes software developed by the OpenSSL Project
37 1.1 christos # for use in the OpenSSL Toolkit (http://www.OpenSSL.org/)"
38 1.1 christos #
39 1.1 christos # THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY
40 1.1 christos # EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
41 1.1 christos # IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
42 1.1 christos # PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE OpenSSL PROJECT OR
43 1.1 christos # ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
44 1.1 christos # SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
45 1.1 christos # NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
46 1.1 christos # LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
47 1.1 christos # HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
48 1.1 christos # STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
49 1.1 christos # ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
50 1.1 christos # OF THE POSSIBILITY OF SUCH DAMAGE.
51 1.1 christos # ====================================================================
52 1.1 christos
53 1.1 christos # Perl script to run tests against S/MIME examples in RFC4134
54 1.1 christos # Assumes RFC is in current directory and called "rfc4134.txt"
55 1.1 christos
56 1.1 christos use MIME::Base64;
57 1.1 christos
58 1.1 christos my $badttest = 0;
59 1.1 christos my $verbose = 1;
60 1.1 christos
61 1.1 christos my $cmscmd;
62 1.1 christos my $exdir = "./";
63 1.1 christos my $exfile = "./rfc4134.txt";
64 1.1 christos
65 1.1 christos if (-f "../apps/openssl")
66 1.1 christos {
67 1.1 christos $cmscmd = "../util/shlib_wrap.sh ../apps/openssl cms";
68 1.1 christos }
69 1.1 christos elsif (-f "..\\out32dll\\openssl.exe")
70 1.1 christos {
71 1.1 christos $cmscmd = "..\\out32dll\\openssl.exe cms";
72 1.1 christos }
73 1.1 christos elsif (-f "..\\out32\\openssl.exe")
74 1.1 christos {
75 1.1 christos $cmscmd = "..\\out32\\openssl.exe cms";
76 1.1 christos }
77 1.1 christos
78 1.1 christos my @test_list = (
79 1.1 christos [ "3.1.bin" => "dataout" ],
80 1.1 christos [ "3.2.bin" => "encode, dataout" ],
81 1.1 christos [ "4.1.bin" => "encode, verifyder, cont, dss" ],
82 1.1 christos [ "4.2.bin" => "encode, verifyder, cont, rsa" ],
83 1.1 christos [ "4.3.bin" => "encode, verifyder, cont_extern, dss" ],
84 1.1 christos [ "4.4.bin" => "encode, verifyder, cont, dss" ],
85 1.1 christos [ "4.5.bin" => "verifyder, cont, rsa" ],
86 1.1 christos [ "4.6.bin" => "encode, verifyder, cont, dss" ],
87 1.1 christos [ "4.7.bin" => "encode, verifyder, cont, dss" ],
88 1.1 christos [ "4.8.eml" => "verifymime, dss" ],
89 1.1 christos [ "4.9.eml" => "verifymime, dss" ],
90 1.1 christos [ "4.10.bin" => "encode, verifyder, cont, dss" ],
91 1.1 christos [ "4.11.bin" => "encode, certsout" ],
92 1.1 christos [ "5.1.bin" => "encode, envelopeder, cont" ],
93 1.1 christos [ "5.2.bin" => "encode, envelopeder, cont" ],
94 1.1 christos [ "5.3.eml" => "envelopemime, cont" ],
95 1.1 christos [ "6.0.bin" => "encode, digest, cont" ],
96 1.1 christos [ "7.1.bin" => "encode, encrypted, cont" ],
97 1.1 christos [ "7.2.bin" => "encode, encrypted, cont" ]
98 1.1 christos );
99 1.1 christos
100 1.1 christos # Extract examples from RFC4134 text.
101 1.1 christos # Base64 decode all examples, certificates and
102 1.1 christos # private keys are converted to PEM format.
103 1.1 christos
104 1.1 christos my ( $filename, $data );
105 1.1 christos
106 1.1 christos my @cleanup = ( "cms.out", "cms.err", "tmp.der", "tmp.txt" );
107 1.1 christos
108 1.1 christos $data = "";
109 1.1 christos
110 1.1 christos open( IN, $exfile ) || die "Can't Open RFC examples file $exfile";
111 1.1 christos
112 1.1 christos while (<IN>) {
113 1.1 christos next unless (/^\|/);
114 1.1 christos s/^\|//;
115 1.1 christos next if (/^\*/);
116 1.1 christos if (/^>(.*)$/) {
117 1.1 christos $filename = $1;
118 1.1 christos next;
119 1.1 christos }
120 1.1 christos if (/^</) {
121 1.1 christos $filename = "$exdir/$filename";
122 1.1 christos if ( $filename =~ /\.bin$/ || $filename =~ /\.eml$/ ) {
123 1.1 christos $data = decode_base64($data);
124 1.1 christos open OUT, ">$filename";
125 1.1 christos binmode OUT;
126 1.1 christos print OUT $data;
127 1.1 christos close OUT;
128 1.1 christos push @cleanup, $filename;
129 1.1 christos }
130 1.1 christos elsif ( $filename =~ /\.cer$/ ) {
131 1.1 christos write_pem( $filename, "CERTIFICATE", $data );
132 1.1 christos }
133 1.1 christos elsif ( $filename =~ /\.pri$/ ) {
134 1.1 christos write_pem( $filename, "PRIVATE KEY", $data );
135 1.1 christos }
136 1.1 christos $data = "";
137 1.1 christos $filename = "";
138 1.1 christos }
139 1.1 christos else {
140 1.1 christos $data .= $_;
141 1.1 christos }
142 1.1 christos
143 1.1 christos }
144 1.1 christos
145 1.1 christos my $secretkey =
146 1.1 christos "73:7c:79:1f:25:ea:d0:e0:46:29:25:43:52:f7:dc:62:91:e5:cb:26:91:7a:da:32";
147 1.1 christos
148 1.1 christos foreach (@test_list) {
149 1.1 christos my ( $file, $tlist ) = @$_;
150 1.1 christos print "Example file $file:\n";
151 1.1 christos if ( $tlist =~ /encode/ ) {
152 1.1 christos run_reencode_test( $exdir, $file );
153 1.1 christos }
154 1.1 christos if ( $tlist =~ /certsout/ ) {
155 1.1 christos run_certsout_test( $exdir, $file );
156 1.1 christos }
157 1.1 christos if ( $tlist =~ /dataout/ ) {
158 1.1 christos run_dataout_test( $exdir, $file );
159 1.1 christos }
160 1.1 christos if ( $tlist =~ /verify/ ) {
161 1.1 christos run_verify_test( $exdir, $tlist, $file );
162 1.1 christos }
163 1.1 christos if ( $tlist =~ /digest/ ) {
164 1.1 christos run_digest_test( $exdir, $tlist, $file );
165 1.1 christos }
166 1.1 christos if ( $tlist =~ /encrypted/ ) {
167 1.1 christos run_encrypted_test( $exdir, $tlist, $file, $secretkey );
168 1.1 christos }
169 1.1 christos if ( $tlist =~ /envelope/ ) {
170 1.1 christos run_envelope_test( $exdir, $tlist, $file );
171 1.1 christos }
172 1.1 christos
173 1.1 christos }
174 1.1 christos
175 1.1 christos foreach (@cleanup) {
176 1.1 christos unlink $_;
177 1.1 christos }
178 1.1 christos
179 1.1 christos if ($badtest) {
180 1.1 christos print "\n$badtest TESTS FAILED!!\n";
181 1.1 christos }
182 1.1 christos else {
183 1.1 christos print "\n***All tests successful***\n";
184 1.1 christos }
185 1.1 christos
186 1.1 christos sub write_pem {
187 1.1 christos my ( $filename, $str, $data ) = @_;
188 1.1 christos
189 1.1 christos $filename =~ s/\.[^.]*$/.pem/;
190 1.1 christos
191 1.1 christos push @cleanup, $filename;
192 1.1 christos
193 1.1 christos open OUT, ">$filename";
194 1.1 christos
195 1.1 christos print OUT "-----BEGIN $str-----\n";
196 1.1 christos print OUT $data;
197 1.1 christos print OUT "-----END $str-----\n";
198 1.1 christos
199 1.1 christos close OUT;
200 1.1 christos }
201 1.1 christos
202 1.1 christos sub run_reencode_test {
203 1.1 christos my ( $cmsdir, $tfile ) = @_;
204 1.1 christos unlink "tmp.der";
205 1.1 christos
206 1.1 christos system( "$cmscmd -cmsout -inform DER -outform DER"
207 1.1 christos . " -in $cmsdir/$tfile -out tmp.der" );
208 1.1 christos
209 1.1 christos if ($?) {
210 1.1 christos print "\tReencode command FAILED!!\n";
211 1.1 christos $badtest++;
212 1.1 christos }
213 1.1 christos elsif ( !cmp_files( "$cmsdir/$tfile", "tmp.der" ) ) {
214 1.1 christos print "\tReencode FAILED!!\n";
215 1.1 christos $badtest++;
216 1.1 christos }
217 1.1 christos else {
218 1.1 christos print "\tReencode passed\n" if $verbose;
219 1.1 christos }
220 1.1 christos }
221 1.1 christos
222 1.1 christos sub run_certsout_test {
223 1.1 christos my ( $cmsdir, $tfile ) = @_;
224 1.1 christos unlink "tmp.der";
225 1.1 christos unlink "tmp.pem";
226 1.1 christos
227 1.1 christos system( "$cmscmd -cmsout -inform DER -certsout tmp.pem"
228 1.1 christos . " -in $cmsdir/$tfile -out tmp.der" );
229 1.1 christos
230 1.1 christos if ($?) {
231 1.1 christos print "\tCertificate output command FAILED!!\n";
232 1.1 christos $badtest++;
233 1.1 christos }
234 1.1 christos else {
235 1.1 christos print "\tCertificate output passed\n" if $verbose;
236 1.1 christos }
237 1.1 christos }
238 1.1 christos
239 1.1 christos sub run_dataout_test {
240 1.1 christos my ( $cmsdir, $tfile ) = @_;
241 1.1 christos unlink "tmp.txt";
242 1.1 christos
243 1.1 christos system(
244 1.1 christos "$cmscmd -data_out -inform DER" . " -in $cmsdir/$tfile -out tmp.txt" );
245 1.1 christos
246 1.1 christos if ($?) {
247 1.1 christos print "\tDataout command FAILED!!\n";
248 1.1 christos $badtest++;
249 1.1 christos }
250 1.1 christos elsif ( !cmp_files( "$cmsdir/ExContent.bin", "tmp.txt" ) ) {
251 1.1 christos print "\tDataout compare FAILED!!\n";
252 1.1 christos $badtest++;
253 1.1 christos }
254 1.1 christos else {
255 1.1 christos print "\tDataout passed\n" if $verbose;
256 1.1 christos }
257 1.1 christos }
258 1.1 christos
259 1.1 christos sub run_verify_test {
260 1.1 christos my ( $cmsdir, $tlist, $tfile ) = @_;
261 1.1 christos unlink "tmp.txt";
262 1.1 christos
263 1.1 christos $form = "DER" if $tlist =~ /verifyder/;
264 1.1 christos $form = "SMIME" if $tlist =~ /verifymime/;
265 1.1 christos $cafile = "$cmsdir/CarlDSSSelf.pem" if $tlist =~ /dss/;
266 1.1 christos $cafile = "$cmsdir/CarlRSASelf.pem" if $tlist =~ /rsa/;
267 1.1 christos
268 1.1 christos $cmd =
269 1.1 christos "$cmscmd -verify -inform $form"
270 1.1 christos . " -CAfile $cafile"
271 1.1 christos . " -in $cmsdir/$tfile -out tmp.txt";
272 1.1 christos
273 1.1 christos $cmd .= " -content $cmsdir/ExContent.bin" if $tlist =~ /cont_extern/;
274 1.1 christos
275 1.1 christos system("$cmd 2>cms.err 1>cms.out");
276 1.1 christos
277 1.1 christos if ($?) {
278 1.1 christos print "\tVerify command FAILED!!\n";
279 1.1 christos $badtest++;
280 1.1 christos }
281 1.1 christos elsif ( $tlist =~ /cont/
282 1.1 christos && !cmp_files( "$cmsdir/ExContent.bin", "tmp.txt" ) )
283 1.1 christos {
284 1.1 christos print "\tVerify content compare FAILED!!\n";
285 1.1 christos $badtest++;
286 1.1 christos }
287 1.1 christos else {
288 1.1 christos print "\tVerify passed\n" if $verbose;
289 1.1 christos }
290 1.1 christos }
291 1.1 christos
292 1.1 christos sub run_envelope_test {
293 1.1 christos my ( $cmsdir, $tlist, $tfile ) = @_;
294 1.1 christos unlink "tmp.txt";
295 1.1 christos
296 1.1 christos $form = "DER" if $tlist =~ /envelopeder/;
297 1.1 christos $form = "SMIME" if $tlist =~ /envelopemime/;
298 1.1 christos
299 1.1 christos $cmd =
300 1.1 christos "$cmscmd -decrypt -inform $form"
301 1.1 christos . " -recip $cmsdir/BobRSASignByCarl.pem"
302 1.1 christos . " -inkey $cmsdir/BobPrivRSAEncrypt.pem"
303 1.1 christos . " -in $cmsdir/$tfile -out tmp.txt";
304 1.1 christos
305 1.1 christos system("$cmd 2>cms.err 1>cms.out");
306 1.1 christos
307 1.1 christos if ($?) {
308 1.1 christos print "\tDecrypt command FAILED!!\n";
309 1.1 christos $badtest++;
310 1.1 christos }
311 1.1 christos elsif ( $tlist =~ /cont/
312 1.1 christos && !cmp_files( "$cmsdir/ExContent.bin", "tmp.txt" ) )
313 1.1 christos {
314 1.1 christos print "\tDecrypt content compare FAILED!!\n";
315 1.1 christos $badtest++;
316 1.1 christos }
317 1.1 christos else {
318 1.1 christos print "\tDecrypt passed\n" if $verbose;
319 1.1 christos }
320 1.1 christos }
321 1.1 christos
322 1.1 christos sub run_digest_test {
323 1.1 christos my ( $cmsdir, $tlist, $tfile ) = @_;
324 1.1 christos unlink "tmp.txt";
325 1.1 christos
326 1.1 christos my $cmd =
327 1.1 christos "$cmscmd -digest_verify -inform DER" . " -in $cmsdir/$tfile -out tmp.txt";
328 1.1 christos
329 1.1 christos system("$cmd 2>cms.err 1>cms.out");
330 1.1 christos
331 1.1 christos if ($?) {
332 1.1 christos print "\tDigest verify command FAILED!!\n";
333 1.1 christos $badtest++;
334 1.1 christos }
335 1.1 christos elsif ( $tlist =~ /cont/
336 1.1 christos && !cmp_files( "$cmsdir/ExContent.bin", "tmp.txt" ) )
337 1.1 christos {
338 1.1 christos print "\tDigest verify content compare FAILED!!\n";
339 1.1 christos $badtest++;
340 1.1 christos }
341 1.1 christos else {
342 1.1 christos print "\tDigest verify passed\n" if $verbose;
343 1.1 christos }
344 1.1 christos }
345 1.1 christos
346 1.1 christos sub run_encrypted_test {
347 1.1 christos my ( $cmsdir, $tlist, $tfile, $key ) = @_;
348 1.1 christos unlink "tmp.txt";
349 1.1 christos
350 1.1 christos system( "$cmscmd -EncryptedData_decrypt -inform DER"
351 1.1 christos . " -secretkey $key"
352 1.1 christos . " -in $cmsdir/$tfile -out tmp.txt" );
353 1.1 christos
354 1.1 christos if ($?) {
355 1.1 christos print "\tEncrypted Data command FAILED!!\n";
356 1.1 christos $badtest++;
357 1.1 christos }
358 1.1 christos elsif ( $tlist =~ /cont/
359 1.1 christos && !cmp_files( "$cmsdir/ExContent.bin", "tmp.txt" ) )
360 1.1 christos {
361 1.1 christos print "\tEncrypted Data content compare FAILED!!\n";
362 1.1 christos $badtest++;
363 1.1 christos }
364 1.1 christos else {
365 1.1 christos print "\tEncryptedData verify passed\n" if $verbose;
366 1.1 christos }
367 1.1 christos }
368 1.1 christos
369 1.1 christos sub cmp_files {
370 1.1 christos my ( $f1, $f2 ) = @_;
371 1.1 christos my ( $fp1, $fp2 );
372 1.1 christos
373 1.1 christos my ( $rd1, $rd2 );
374 1.1 christos
375 1.1 christos if ( !open( $fp1, "<$f1" ) ) {
376 1.1 christos print STDERR "Can't Open file $f1\n";
377 1.1 christos return 0;
378 1.1 christos }
379 1.1 christos
380 1.1 christos if ( !open( $fp2, "<$f2" ) ) {
381 1.1 christos print STDERR "Can't Open file $f2\n";
382 1.1 christos return 0;
383 1.1 christos }
384 1.1 christos
385 1.1 christos binmode $fp1;
386 1.1 christos binmode $fp2;
387 1.1 christos
388 1.1 christos my $ret = 0;
389 1.1 christos
390 1.1 christos for ( ; ; ) {
391 1.1 christos $n1 = sysread $fp1, $rd1, 4096;
392 1.1 christos $n2 = sysread $fp2, $rd2, 4096;
393 1.1 christos last if ( $n1 != $n2 );
394 1.1 christos last if ( $rd1 ne $rd2 );
395 1.1 christos
396 1.1 christos if ( $n1 == 0 ) {
397 1.1 christos $ret = 1;
398 1.1 christos last;
399 1.1 christos }
400 1.1 christos
401 1.1 christos }
402 1.1 christos
403 1.1 christos close $fp1;
404 1.1 christos close $fp2;
405 1.1 christos
406 1.1 christos return $ret;
407 1.1 christos
408 1.1 christos }
409 1.1 christos
410